Add OIDC authentication and Kubernetes RBAC to Console - #1787
Conversation
|
/kelos review |
|
🤖 Kelos Task Status Task |
|
🤖 Kelos Reviewer Agent @gjkim42 Review SummaryVerdict: APPROVE Findings Overview
FindingsDocumentation accuracy
Correctness
Suggestions (optional)
Key takeaways
|
There was a problem hiding this comment.
All reported issues were addressed across 28 files
Tip: cubic can generate docs of your entire codebase and keep them up to date. Try it here.
Re-trigger cubic
92ac19d to
ddc603d
Compare
|
Addressed the Kelos reviewer findings in The valid inline findings are fixed or clarified, including the reserved-prefix bypass. The subject-claim report was verified against the pinned upstream source and existing integration assertion; the schema-placement suggestion retains the existing pre-deployment render checks. Explanations are recorded in those threads. The PR is squashed to one commit and pushed with |
There was a problem hiding this comment.
All reported issues were addressed across 15 files (changes from recent commits).
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
ddc603d to
b076a91
Compare
b076a91 to
ec082a0
Compare
What type of PR is this?
/kind feature
What this PR does / why we need it:
The shared Console token gives every holder the server ServiceAccount's authority. Add opt-in OIDC authentication through an OAuth2 Proxy sidecar and per-user Kubernetes SubjectAccessReview checks, so operators can grant Console access through namespace RoleBindings.
Which issue(s) this PR is related to:
Fixes #1450
Special notes for your reviewer:
No users receive permissions automatically. Operators must configure an OIDC client, HTTPS ingress, an existing Secret, and namespace RoleBindings.
sessions/connectgrants full interactive chat and shell access; general Session patch permissions also allow lifecycle changes. Existing WebSockets retain access until disconnected. New requests and connections perform fresh authorization checks, while IdP changes remain subject to proxy refresh/expiry.Validation:
make test TEST_FLAGS='-count=1 -run=TestConsoleBrowserAuthentication'passed with workspace token/Codex environment variables removed. The browser identity test requires exactly one request to/api/config.env -u CODEX_AUTH_JSON -u CODEX_HOME make testpassed. The two variables were removed only from the test process because inherited workspace configuration affects existing entrypoint tests.make test-integration TEST_FLAGS='-count=1 -run=TestConsoleOIDC'passed using the rendered configuration, the real OAuth2 Proxy binary, a local test issuer, and an envtest Kubernetes API server with RBAC. Covers two identities, namespace isolation, forged headers, inventory relationships, suspend/resume, WebSocket upgrades/reconnects, revocation, and logout. Envtest has no kubelet; successful stream operations, attachment transfers, and Task logs are covered with unit-test fakes.make verify,make build WHAT=cmd/kelos-console-server, andgit diff --checkpassed.-race. Cluster e2e validation is left to PR CI.UI comparison: the same 1280×900 Settings view and empty namespace fixture, rendered from the base and PR frontend assets. The after image supplies the OIDC username through the config API fixture; these screenshots illustrate the UI, not a live IdP deployment.
Before — shared-token mode
After — OIDC mode
Does this PR introduce a user-facing change?
Summary by cubic
Adds opt-in OIDC authentication to the Console through an OAuth2 Proxy sidecar, with per-user Kubernetes RBAC authorization. Static-token authentication remains the default.
New Features
kelos-console-useron uninstall.Migration
Fixes #1450.
Written for commit ec082a0. Summary will update on new commits.